Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

341–350 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#341
This is upsetting. I currently use macOS with iCloud, FaceTime, iMessage, and App Store all disabled, and use Little Snitch to prevent the machine from communicating with Apple except for on update days, and then limited only to those specific update processes.

It’s possible that this will mean that the next macOS version will be unsuitable on privacy grounds, as I will then have to use a second physical device to prevent such network access. :(

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#342

Everyone seems to assume this is true, but are people also confirming this? I installed LittleSnitch recently on Big Sur and I’m constantly getting pop up’s for all of Apple’s internal daemons etc. While I haven’t tried the App Store specifically, I’m wondering if the person didn’t understand how things were configured and was allowing certain traffic thru. I can’t imagine there’s really some big conspiracy here.

The tweeter is Patrick Wardle, security researcher and creator of Objective-See[1] which publishes several macOS security apps, including the LuLu firewall. Given Patrick’s track record, it’s generally safe to assume due diligence was given to the claim and that lack of understanding about configuration doesn’t apply.

As to your specific case, the tweet does mention “many of” Apple’s apps are affected (i.e. not all, not even necessarily the majority).

[1]: https://objective-see.com/

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#343
post #37

I trust Apple a lot more than I trust Google or Facebook, but this clamping down of the Mac without options for power users while officially stating that the Mac will remain a Mac is alarming and distasteful on the part of Apple. With the transition to Apple’s own chips looming, it seems like the days of “a Mac is a personal computer and not an app console like an iPhone or iPad” will be over by the middle of this de…

All of these companies are equally subject to the spying mandates of the US military intelligence community, an organization that no one should trust due to many decades of history operating entirely outside of the law.

Trust Apple, fine. But don’t trust the CIA, which gets access to the whole of Apple’s data, taken by threat of force under spying programs.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#344
post #167

Earlier quoted context omitted.

I don't believe this is ever the case. What happens if you legitimately installed a new keyboard? Will Apple just... prevent you from using it?

I have a 2017 MBP. There are several keycaps that that are no longer physically connected to the key, so if I tilt the laptop 4 or 5 keys fall off. I have been dealing with it by using an external Apple keyboard (with added benefit of having 10-key and full sized arrow keys). Since it's on a desktop in this config, I have it set to never sleep so luckily I have not seen this unwakeable fuck up.

> Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route.

I had the same thing happening to me but Apple changed the complete keyboard under their extended keyboard warranty programm (even though it was out of Apple Care already).

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#345

Earlier quoted context omitted.

I have a 2017 MBP. There are several keycaps that that are no longer physically connected to the key, so if I tilt the laptop 4 or 5 keys fall off. I have been dealing with it by using an external Apple keyboard (with added benefit of having 10-key and full sized arrow keys). Since it's on a desktop in this config, I have it set to never sleep so luckily I have not seen this unwakeable fuck up.

Apple has a three year warranty which means yours may have run out or is about to run out. If you still have time, get your keyboard replaced for free: https://support.apple.com/keyboard-service-program-for-mac-n... (it also means they have to replace your mobo and battery due to brilliant Apple engineering). It doesn't fix the problem, but it resets the clock until they fall off again. In Texas, it was <48 hours bet…

48 hours is pretty optimistic. At least for the 2016 model they can't just change the keycaps but they'll have to change the whole bottom case. This took a few weeks for me since I had to send it to a certified repair center.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#346

Earlier quoted context omitted.

>Yes, I use pcmanfm on Linux and the spacebar will open the file in the default program. That's not what QuickLook does. It allows the user to get a "quick look" at a file without launching a default application. Also, in macOS you get access to QuickLook from inside any application's Open dialog. That's a huge time saver when you have similar files and just need to see which one before doing a full open. Think large…

Dumb question: How does this differ from setting the view in the file selector to thumbnails?

Thumbnails might work for a folder of images. However, QuickLook will also allow you to preview a video, Word Doc, PDF, spreadsheet, and text files including source code. It's honestly my favorite feature of the OS.

Trying to attach a file to an email, but not sure it's the right one? QuickLook allows you to view the document in the Open dialog. Once you use it, it is something you will just accept as natural and only notice it not being available on other OSes.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#347

Everyone seems to assume this is true, but are people also confirming this? I installed LittleSnitch recently on Big Sur and I’m constantly getting pop up’s for all of Apple’s internal daemons etc. While I haven’t tried the App Store specifically, I’m wondering if the person didn’t understand how things were configured and was allowing certain traffic thru. I can’t imagine there’s really some big conspiracy here.

Confirmed. Someone also found the strings in the network stack, which are tested against the app's bundle identifier to provide these wholes. It's ridiculous.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#348
post #334

I wonder if it would make sense for Little Snitch to continue supporting their kext-based solution in parallel to the new one, possibly only for users who are willing to disable SIP. You might argue that disabling SIP for a security product defeats the point, but I'm not sure if that's necessarily true. SIP effectively delegates trust away from the user and towards Apple, which is fine as a default—but the calculus m…

Eventually I don't think little snitch will even have apis to access stuff like that in the kernel as a kext as macos updates continue on.

Kexts are used by Apple internally, so I'd be shocked if they were removed from the OS completely. Third party kexts may be deprecated, but as long as SIP can be disabled it will always be possible to load your own.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#349
post #226

Earlier quoted context omitted.

Apple touted the T2 chip as the bee's knees in security. Now, we have a vulnerability that cannot be defended against. However, Apple went all in on the security of this T2 chip so that you cannot replace the SSD (besides the method to manufacture). I appreciate the desire at making a device difficult for a bad actor to get to your data, but they epicly failed and ultimately only made an user-hostile device. Oh, and…

T2 is a nightmare for people who want to reinstall. I reinstalled a machine for someone and it was a mess of 2fa and other nonsense.

Yeah if you want to wipe a laptop, make sure you unlink your user account first. It's Apple's theft protection, same as with their phones. It'll want to see a successful login with the Apple ID.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#350

Earlier quoted context omitted.

Adobe doesn't care to support Linux. It's as simple as that.

That's an obvious drive by answer, but I'm asking a forum of developers for an explanation/guess on what it is about Linux that would make Adobe not care about it.

The small user-base. It's a feedback loop; people don't use Linux because a lot of software isn't there, and developers don't port the software to Linux because people don't use Linux.
Post reply on HN